1. Site operator and contact
Free HTL Guide is an independent educational website operated by Natnale Mengesha. Privacy questions and data requests may be sent to withnati@gmail.com.
This website is not affiliated with or endorsed by ASCP or the ASCP Board of Certification.
2. Public and anonymous learning
You may use approved public learning content without creating an account. While signed out, study progress such as lesson location, completed tasks, quiz results, saved flags, unfinished practice sessions, theme choice, and analytics choice may be stored in your browser.
Anonymous browser progress stays on that device unless you later sign in and explicitly choose to import it. Clearing browser storage removes the locally stored information from that browser. Free HTL Guide does not use anonymous browser progress as proof of identity or premium entitlement.
3. Learner accounts and authentication
Learner accounts are provided through Supabase. When you create or use an account, Supabase processes information needed for authentication, including:
- The email address you provide.
- A display name if you choose to provide one.
- A unique account identifier.
- Email-verification, sign-in, recovery, password-reset, session, and security timestamps.
- Technical information needed to detect, maintain, and secure an authenticated session.
Passwords are submitted to the authentication provider and are not stored in the Free HTL Guide learner-progress tables. Do not reuse a password from another service.
Authentication proves account identity only. A verified account does not automatically grant paid or premium access.
4. Cloud-backed learning progress
After signing in, you are given a deliberate choice to import existing anonymous browser progress and enable cloud synchronization, or to use account progress only. Cloud progress may include:
- Module and study-task identifiers, completion state, and activity timestamps.
- Stable attempt and session identifiers.
- Quiz, mock-exam, and Targeted Practice type, mode, score, duration, and domain results.
- Question, source-question, and selected-option identifiers needed to reconstruct progress.
- Flags, unfinished-session responses, revisions, migration records, and synchronization metadata.
Cloud progress is designed not to store full question text, answer explanations, complete answer keys, personal notes, analytics consent, theme choice, or your email address in the learner-progress tables.
Completed attempts use stable identifiers to prevent duplicates. Mutable unfinished sessions use revisions and explicit conflict choices so an older device cannot silently overwrite newer account progress.
5. Offline recovery and browser copies
When cloud progress is enabled, the browser may temporarily retain a user-scoped pending-write queue and a last-known cloud cache. These copies support offline use, failed-write recovery, and visible Saving, Saved, Offline, Sync problem, and Conflict states.
A local anonymous or recovery copy may remain temporarily until you deliberately reset or remove it. Signing out does not convert browser metadata into entitlement and does not expose another account's cloud progress.
6. Premium entitlement and protected content
Where premium access is tested or offered, the server may store an entitlement record tied to the authenticated user. That record may include a product code, access status, effective dates, cancellation, expiration or revocation dates, source, source reference, and an audit history of changes.
Entitlement records are server-controlled and are not editable by learners. Browser storage, URL parameters, profile fields, successful return pages, or hidden page elements do not grant premium access.
Protected lessons, question banks, explanations, answer keys, and downloads are intended to be delivered only after a server verifies the account session and effective entitlement. Protected learning content is not copied into the learner-progress database.
Payment checkout is not active during the current Layer 14 development phase. This policy will be updated before a production payment provider begins processing purchases.
7. Account export, reset, and deletion
Account settings provide deliberate controls for eligible progress export, progress reset, and account deletion. Exports and resets use explicit field allowlists.
Account deletion requires exact confirmation and an authenticated request to a Supabase Edge Function. The server derives the account identity from the verified bearer token rather than accepting a caller-supplied user ID. Deleting the authentication account cascades through learner-owned progress records.
After successful deletion, account and progress keys are cleared from that browser while unrelated theme and privacy preferences may remain. Provider backups and security logs may persist for a limited period under operational, legal, or abuse-prevention requirements.
8. Optional email updates
The optional email-update form may collect:
- The email address you enter.
- Your affirmative consent to receive occasional Free HTL Guide resource and module updates.
- Basic form metadata such as the source page and subscription type.
Email signup submissions are processed through Formspree so the request can be reviewed and, when configured, confirmed. Do not submit patient, health, employment, financial, or other sensitive information through the email form.
Email addresses are not sold or used for third-party advertising. You may stop future messages through an unsubscribe link included in an email or by sending an unsubscribe request.
9. Optional analytics and explicit consent
Google Analytics 4 is configured, but analytics is available only after explicit consent. The Google tag does not load until a visitor chooses Allow analytics through the site's Privacy choices control. Declining analytics is remembered on that device and prevents the Google analytics tag from loading. You may reopen Privacy choices and change the decision later.
The approved event set is limited to page and feature usage such as page views, module openings, scroll milestones, file downloads, quiz starts and completion percentages, study-task toggles, sharing actions, and email-signup success or failure.
The analytics contract prohibits email addresses, personal names, personal notes, quiz answers, question-level responses, patient information, account user IDs, and complete URL query strings or fragments. Google Signals and advertising-personalization settings are disabled in the site configuration. The intended GA4 event-data retention setting is 14 months.
10. Privacy choices and device storage
The Privacy choices control provides equally available Allow analytics and Decline analytics choices. No optional analytics events are transmitted unless the saved choice is Allow analytics.
Browser local storage or session storage may also hold theme choice, anonymous progress, account-session material managed by Supabase, cloud-sync decisions, pending writes, recovery caches, and short-lived interface state. Browser storage is origin-specific, which is one reason the planned production account experience will use a dedicated website origin rather than the shared GitHub Pages origin.
Do not use shared or public computers for a persistent account session. Sign out and clear browser data when appropriate.
11. Hosting, service providers, and technical logs
The current development site is hosted through GitHub Pages. The approved production architecture uses Cloudflare Pages for the public frontend and Supabase for authentication, database, Edge Functions, and private content storage. Production migration is not complete until the Layer 14 staging and cutover checks are approved.
These providers and network services may process ordinary technical data such as IP address, browser and device information, request time, requested path, response status, security events, and service logs as necessary to operate and secure their systems.
Protected-content logs are designed to record a request reference, status, decision category, content identifier, function version, and latency without logging bearer tokens, passwords, complete protected payloads, answer keys, explanations, or service credentials.
12. Security and access controls
Free HTL Guide uses measures such as encrypted HTTPS connections, Supabase session validation, Row Level Security on learner-owned database tables, exact origin allowlists for privileged functions, private storage, server-only service credentials, conflict protection, automated testing, and controlled deployment procedures.
No online service can guarantee absolute security. Please report suspected unauthorized account or content access promptly and avoid sending passwords, access tokens, or sensitive laboratory or patient information by email.
13. Retention and sharing
Information is retained only as long as reasonably needed to provide the requested service, preserve learner progress, maintain account and entitlement integrity, process suppression or unsubscribe records, investigate abuse, recover from failures, or satisfy legal and operational requirements.
Information may be shared with service providers needed to operate the website, authentication, cloud progress, hosting, email form, private content delivery, or consented analytics, and when disclosure is legally required. Personal information is not sold.
Optional GA4 analytics uses a 14 months event-data retention setting. Aggregate reports may remain available beyond the underlying user-level event retention period.
14. Your choices and requests
Depending on the information involved, you may:
- Use public learning while signed out.
- Decline or later change optional analytics through Privacy choices.
- Choose whether to import anonymous progress into an account.
- Use account progress without importing the browser copy.
- Export or reset eligible progress through Account settings.
- Update your display name or password.
- Delete your account and learner-owned cloud progress.
- Unsubscribe from optional email updates.
- Request access, correction, or deletion of information by contacting the site operator.
For security, identity verification may be required before acting on an account-specific request.
15. Children and educational scope
The site is intended for adult learners and laboratory professionals and is not designed to knowingly collect personal information from children under 13.
Educational content and progress indicators do not replace official examination guidance, validated laboratory procedures, safety requirements, regulatory obligations, institutional policy, or professional judgment.
16. Policy changes
This policy may be revised when hosting, account functionality, protected delivery, analytics settings, email providers, payment processing, or legal requirements change. The effective date will be updated when material changes are published.
Before a paid launch, this policy will be reviewed again to describe the selected payment provider, subscription records, billing support, and any additional retention or disclosure requirements.